Source-linked AI summary

Field test of quantum key distribution in the Tokyo QKD Network

M. Sasaki, M. Fujiwara, H. Ishizuka, W. Klaus, K. Wakui, M. Takeoka, A. Tanaka, K. Yoshino, Y. Nambu, S. Takahashi, A. Tajima, A. Tomita, T. Domeki, T. Hasegawa, Y. Sakai, H. Kobayashi, T. Asai, K. Shimizu, T. Tokura, T. Tsurumaru, M. Matsui, T. Honjo, K. Tamaki, H. Takesue, Y. Tokura, J. F. Dynes, A. R. Dixon, A. W. Sharpe, Z. L. Yuan, A. J. Shields, S. Uchikoga, M. Legre, S. Robyr, P. Trinkler, L. Monat, J. -B. Page, G. Ribordy, A. Poppe, A. Allacher, O. Maurhart, T. Langer, M. Peev, A. Zeilinger

arXiv:1103.3566v1quant-ph

TL;DR

The paper addresses the need to make QKD useful in metropolitan applications requiring stronger performance and practical network operation. It integrates heterogeneous QKD systems through shared management and demonstrates secure communications, sustained key generation, and rerouting in the Tokyo QKD Network. The trial supports secure TV conferencing and mobile-phone applications while identifying implementation security and broader service functionality as continuing boundaries.

  • Problem

    Field QKD links typically provided a few kbps over a few tens of kilometers, limiting applications beyond voice encryption or feeding a classical encryptor.

  • Method

    The Tokyo QKD Network integrates different QKD schemes and devices through common key-management interfaces and a single key-management server.

  • Results

    The trial demonstrated secure TV conferencing, eavesdropping detection, QKD-link rerouting, stable key generation, and a 304 kbps average secure key rate over a 45 km field link.

  • Takeaways & Limitations

    The demonstrations indicate that practical QKD applications in a metropolitan network may be feasible, including secure TV conferencing and mobile-phone use.

  • Takeaways & Limitations

    Real-world QKD implementations remain susceptible to side-channel attacks, so continued testing is needed to identify loopholes and develop countermeasures.

Abstract

from arXiv · show

A novel secure communication network with quantum key distribution in a metropolitan area is reported. Different QKD schemes are integrated to demonstrate secure TV conferencing over a distance of 45km, stable long-term operation, and application to secure mobile phones.

1. Introduction

QKD addresses the challenge of distributing the long keys required for information-theoretically secure one-time-pad encryption. Field networks have demonstrated multi-user operation, but distance, secure key rate, and practical applications remain constrained, motivating the Tokyo metropolitan network.

  • 1. Introduction: The one-time pad is the only encryption method identified as information-theoretically secure against an eavesdropper with unbounded ability.Its key must be used once and be as long as the message.
  • 1. Introduction: QKD provides a way to deliver one-time-pad key material over optical networks, building on experimental, theoretical, and commercial progress.QKD development moved from laboratory demonstrations toward real-world use, while practical-system security analysis and commercialization advanced.
  • 1. Introduction: Multi-user QKD field networks have used actively switched optical networks and integrated heterogeneous systems through cross-platform interfaces.The DARPA Quantum Network pioneered field deployment, while SECOQC developed a quantum backbone network integrating different QKD systems.
  • 1. Introduction: Trusted-node key relay expands distribution distance but requires physically secure relay nodes, whereas transparent optical switching reduces key-management complexity but is limited by optical loss.The appropriate scheme depends on the network purpose and infrastructure.
  • 1. Introduction: Typical field performance of a few kbps over a few tens of kilometers supported real-time one-time-pad voice encryption or session-key feeding, but higher rates were needed for broader applications.The paper therefore presents the Tokyo QKD Network as a metropolitan trusted-node network targeting secure TV conferencing and mobile-phone use.

2. Outline of the Tokyo QKD Network

The Tokyo QKD Network is a metropolitan testbed combining multiple QKD systems across a mesh of access points and links. A shared API, layered architecture, and network wiring connect heterogeneous devices and organizations for interoperable operation.

  • 2. Outline of the Tokyo QKD Network: The physical network is a mesh with loopback links using parallel fibers, while the logical configuration has six nodes and link distances from 1 km to 90 km.The figure identifies the four access points and six kinds of installed QKD systems.
  • 2. Outline of the Tokyo QKD Network: The network uses four access points—Koganei, Otemachi, Hakusan, and Hongo—with six QKD links formed by Japanese and European organizations.The access points are connected by commercial fiber bundles, and the field operation involved nine organizations from Japan and the EU.
  • 2. Outline of the Tokyo QKD Network: The trial established a common API compatible with the SECOQC QBB Link Interface to interconnect Japanese and European QKD systems.Software compatibility enabled smooth interconnection among heterogeneous QKD devices.
  • 2. Outline of the Tokyo QKD Network: The wiring uses separate paths for quantum and classical information on the QKD links, with key-management agents isolated from one another by Layer-2 switching.Links 1, 3, 5, and 6 use a second fiber for classical information and synchronization; links 2 and 4 use a second local-area-network fiber.
  • 2. Outline of the Tokyo QKD Network: The network is organized into quantum, key-management, and communication layers.The wiring diagram implements the layered architecture using optical fibers for quantum links and separate fibers or local-area-network paths for classical information and synchronization.

3. QKD systems used in the Tokyo QKD Network

The Tokyo QKD Network integrated multiple QKD systems and supporting technologies to provide high-speed metropolitan secure communication, stable operation, and practical applications including video and smartphone telephony.

  • Network-wide integration: High-speed NEC-NICT and TREL systems enabled real-time secure video conferencing in the metropolitan network.The network also included NTT long-distance voice communication, Mitsubishi smartphone telephony, IDQ commercial operation, and All-Vienna entanglement-based QKD.
  • TREL system: 304 kbps average secure bit rate was sustained over 24 hours on the 45 km Otemachi-Koganei field link despite 14.5 dB loss.The field and laboratory rates allowed secure one-time-pad video transmission, and the authors report an increase of over two orders of magnitude over their previous SECOQC field-test results.
  • NTT-NICT system: NTT demonstrated stable 90 km operation with approximately 2.1 kbps secure key generation, sufficient for real-time one-time-pad voice encryption.Sifted-key generation remained stable for more than 8 days, while secure-key generation was demonstrated for about 4 hours.
  • Applications and additional systems: QKD was extended to smartphone voice encryption, while IDQ reduced QBER from 4% to approximately 2% using spectral filtering to mitigate crosstalk noise.All-Vienna used BBM92 entanglement-based QKD, and the AIT software framework was released under an open-source license for adaptation and validation.

4. Demonstration of secure network operation

The Tokyo QKD Network demonstrated secure metropolitan video conferencing with redundant QKD relay routes, attack detection, and continued operation after rerouting.

  • Secure TV conferencing: 128 kbps video was encrypted by one-time pad using keys supplied through two QKD relay routes spanning 135 km and 69 km.The route via Koganei-2 was primary, while the route via Otemachi-1 provided an alternative.
  • Secure TV conferencing: The network configuration connected conferencing systems at Koganei-1 and Otemachi-2 through a JGN2plus L2-VPN.The VPN carried the encrypted live video stream between the two sites.
  • Attack detection: A photon-stream interception and laser-injection attack caused a sudden QBER increase, which the KMS detected within seconds and used to stop the QKD link.The demonstration used a high-reflective mirror to tap the fiber and injected a continuous-wave laser at matching power.
  • Rerouting and relay: The secure conference continued without interruption after security controls detected the attack and QKD links were rerouted.The network also successfully tested key relay over additional routes involving Koganei-3 and Hongo.
  • Network and monitoring views: Figure 18 depicts the two relaying QKD routes, while Figure 19 shows KMS states before and immediately after attack detection.The red route passes through Koganei-2 and the blue route through Otemachi-1.

5. Conclusions and Future Outlook

The Tokyo QKD Network field trial integrated multiple QKD systems and key-management components to demonstrate practical metropolitan applications. Future work targets long-term implementation security, scalable networking, photonic-network integration, and broader cryptographic services.

  • Conclusions: The trial integrated novel GHz-clocked QKD systems, a QKD smartphone, a commercial QKD product, and an entanglement QKD system through common key-management interfaces.A single key-management server managed the interconnected systems.
  • Conclusions: Secure TV conferencing used QKD one-time-pad encryption over two trusted-node-relayed routes, with rerouting after eavesdropper detection.The rerouting function switched from a hacked link to an alternative secure link.
  • Future security requirements: Long-term practical deployment requires both stable QKD operation and security assurance over extended periods.Implementation imperfections require explicit assumptions, side-channel investigation, and appropriate countermeasures.
  • Future networking: Scalable multipoint networks with multicasting require more efficient key management, while network coding may reduce secure-key consumption.These are identified as future networking issues.
  • Photonic-network integration: Integrating QKD into photonic networks would support quantum networking in optical infrastructures that process signals within the optical domain.The outlook includes direct realization of efficient QKD links through optical cross-connects and reconfigurable optical add-drop multiplexers.
  • Broader applications: Future QKD applications may extend beyond confidentiality to message authentication, identification, and digital signatures.Identification and digital signatures require further research and may involve additional assumptions or quantum resources.
Loading 1103.3566v1…